Automation Device Certificate Update Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing automation systems face challenges in efficiently tracking and managing digital device certificates when device configurations change, leading to potential communication failures and incorrect data interpretation.

Innovation Solution

An automation device automatically updates its digital device certificate with device-specific configuration data after a configuration change, allowing seamless authentication and secure communication with authentication partners by using predefined certificates or an integrated issuing unit to generate variable device certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If device configuration changes are allowed to improve adaptability, then device versatility is improved, but certificate validity and authentication reliability deteriorate because existing certificates become outdated

Engineering Contradiction:
Improvedevice configuration flexibilityVSAvoidcertificate authentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic certificate management where certificates are automatically updated when device configuration changes. The system transitions from static certificates to dynamic certificates that adapt to configuration changes, ensuring certificate validity while maintaining authentication reliability through automated renewal processes

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent establishes a feedback mechanism where the system monitors device configuration changes and automatically triggers certificate updates. The authentication partner receives notifications about configuration changes and can verify updated certificates, creating a closed-loop system that maintains reliability while allowing configuration flexibility

Inventive Principle:
Principle #23Feedback

2Reliability

If manual certificate updates are implemented to maintain reliability, then authentication reliability is preserved, but operational complexity and time consumption increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcertificate update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service automated certificate management where the automation device automatically detects configuration changes, generates updated certificates, and manages the update process without manual intervention. This eliminates time-consuming manual operations while maintaining authentication reliability through systematic automated processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary actions by pre-generating updated certificates before configuration changes take effect. The system prepares replacement certificates in advance, ensuring seamless transitions without operational interruptions or time losses during actual configuration updates

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If configuration changes are permitted to enhance adaptability, then device versatility improves, but data accuracy and measurement reliability worsen due to outdated configuration data in certificates

Engineering Contradiction:
Improveconfiguration adaptabilityVSAvoiddata interpretation accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where authentication partners receive real-time notifications about configuration changes. This enables them to obtain updated configuration data through authenticated communication channels, ensuring data interpretation accuracy is maintained while allowing configuration flexibility

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary authentication system that mediates between configuration changes and data interpretation. The authentication partner serves as an intermediary that verifies updated certificates and ensures configuration data accuracy is maintained throughout the system, enabling both adaptability and precision

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2936259B1Updating of a digital device certificate of an automation device
Publication Date: 2019.06.12 SIEMENS AG
  • EP2936259B1 patent drawingFigure 1
  • EP2936259B1 patent drawingFigure 2
  • EP2936259B1 patent drawingFigure 3~4

AI summary

The invention relates to an automation device (41, 81), a system and a method for updating a digital device certificate (55, 86, 96) of an automation device (41, 81) of an automation system, wherein the automation device (41, 81) is authenticated to an authentication partner by means of at least one device certificate (55, 86, 96). The device certificate (55, 86, 96) is connected to device-specific configuration data of the automation device (41, 81). Following a modification of the configuration of the automation device (41, 81), according to the invention an updated device certificate (55, 86, 96) having device-specific configuration data according to the modified configuration of the automation device (41, 81) is determined by the automation device (41, 81) and subsequently used for authentication.